Created attachment 280480 [details] [TEST] JS Reduction * SUMMARY Eager FTL failure for strict comparison of NaN with number check * TEST function isNaNOnDouble(value) { return (+value) !== value; } noInline(isNaNOnDouble); function testIsNaNOnDoubles() { var value = isNaNOnDouble(-0); if (value) throw "isNaNOnDouble(-0) = " + value; var value = isNaNOnDouble(NaN); if (!value) throw "isNaNOnDouble(NaN) = " + value; var value = isNaNOnDouble(Number.POSITIVE_INFINITY); if (value) throw "isNaNOnDouble(Number.POSITIVE_INFINITY) = " + value; } noInline(testIsNaNOnDoubles); for (var i = 0; i < 1e6; ++i) { testIsNaNOnDoubles(); } * STEPS TO REPRODUCE 1. $ DYLD_FRAMEWORK_PATH=$build/Release $build/Release/jsc --useFTLJIT=true --useConcurrentJIT=false --thresholdForJITAfterWarmUp=100 --thresholdForJITAfterWarmUp=10 --thresholdForJITSoon=10 --thresholdForOptimizeAfterWarmUp=20 --thresholdForOptimizeAfterLongWarmUp=20 --thresholdForOptimizeSoon=20 --thresholdForFTLOptimizeAfterWarmUp=20 --thresholdForFTLOptimizeSoon=20 number-compare-strict.js Exception: isNaNOnDouble(NaN) = false * NOTES - The issue only reproduces if --useConcurrentJIT=false
I'll take it. Scary stuff.
<rdar://problem/26634629>
Created attachment 280501 [details] Patch
Comment on attachment 280501 [details] Patch Clearing flags on attachment: 280501 Committed r201678: <http://trac.webkit.org/changeset/201678>
All reviewed patches have been landed. Closing bug.